The aspect improves discovery, but it is descriptive metadata rather than an access-control boundary. In a production version I would classify sensitive columns, attach policy tags or masking rules at the column level, and grant the connection service account only the storage permissions required for this object prefix. It is also worth testing that a user who can discover the table cannot query protected fields. That separates successful catalog enrichment from actual data protection.
Ahmet Özel
AI Engineer. Computer Vision, RAG and LLM agents.
The aspect improves discovery, but it is descriptive metadata rather than an access-control boundary. In a production version I would classify sensitive columns, attach policy tags or masking rules at the column level, and grant the connection service account only the storage permissions required for this object prefix. It is also worth testing that a user who can discover the table cannot query protected fields. That separates successful catalog enrichment from actual data protection.